Site navigation

Microsoft: Russian Hackers Targeting UK Critical Industries

Staff Writer

,

russian hackers
Microsoft has warned that the Seashell Blizzard hacking group is taking advantage of common flaws in internet-facing networks in the UK and US, with their target being systems in critical sectors.

Hackers with links to Russian military intelligence have been discovered targeting critical networks across sensitive sectors such as energy, telecommunications, shipping, and arms manufacturing, and have already compromised some networks in the UK and US, according to Microsoft.

The tech giant’s Threat Intelligence team posted a blog detailing the nefarious activities of a subgroup from within Seashell Blizzard, a threat actor with links to the Russian GRU, which since 2021 has been observed leveraging opportunistic access techniques to break into internet-facing systems around the world.

Dubbed by Microsoft as the ‘BadPilot campaign’, the Seashell Blizzard subgroup began its operations focused on Eastern Europe as well as central and southern Asia, and are alleged to have enabled at least three destructive cyber-attacks against Ukraine.

The threat group, which also goes by Voodoo Bear, Blue Echidna, Sandworm, PHANTOM, BlackEnergy Lite, and APT44, uses distinctive exploits, tooling, and infrastructure, limiting the tailoring of attacks and often relying on a ‘spray and pray’ approach to achieving compromises at scale.

These attacks, which have included assaults on supply chains as well as ransomware incidents, suggests that Seashell Blizzard has been tasked with obtaining access to high-priority targets that could provide the Russian military and government a range of options for future actions. 

However, since early 2024 the group has expanded to targets in the US and UK, with Microsoft saying it has exploited vulnerabilities in the ConnectWise ScreenConnect IT remote management and monitoring software, and Fortinet FortiClient EMS security applications.

Microsoft said that, to date, at least eight common vulnerabilities had been exploited by the group, including within Microsoft Outlook, and Microsoft Exchange, alongside flaws in OpenFire, JBOSS, and Zimbra Collaboration, with Seashell Blizzard using third-part services and direct scanning to discover internet-facing networks.

Once inside a network, the hackers have deployed remote management and monitoring (RMM) software to maintain their access to critical functions, all while masquerading as a legitimate utility, making detection much less likely.

The group has also been observed deploying web shells, malicious files injected into webservers that can be executed from browsers to retain and expand access, as well as DNS manipulation for further credential harvesting.

To harden networks against the Seashell Blizzard activity, Microsoft said that security teams should look to implement a vulnerability management system, set up multifactor authentication, and enable network level authentication for remote desktop service connections.  


Recommended reading


“Given that Seashell Blizzard is Russia’s cyber tip of the spear in Ukraine, Microsoft Threat Intelligence assesses that this access subgroup will continue to innovate new horizontally scalable techniques to compromise networks both in Ukraine and globally in support of Russia’s war objectives,” concludes the warning.

Microsoft’s threat alert follows a recent similar report from Google’s Threat Intelligence Group, which said that high-level, state-sponsored attackers are using genAI to support and accelerate their malicious activities.

According to Google, Russian-linked threat groups have been witnessed trying to use Google’s Gemini tool for coding tasks, including converting malware into other coding languages and adding encryption functions to existing code, in the hope of making their future attacks more efficient.   

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences